ctipilot.ch

Gogs argument-injection RCE

trend · trend:gogs-unpatched-argument-injection-rce-rapid7-metasploit

Rapid7 publishes an unpatched Gogs argument-injection RCE together with a Metasploit module.

Coverage timeline
4
first 2026-05-25 → last 2026-06-29
Peak priority
high
2 high · 2 notable
Sources cited
17
13 hosts
Sections touched
3
active-threats, updates, weekly-looking-ahead
Co-occurring entities
1
see Related entities below
ATT&CK techniques
6
pinned v19.1 · see below

ATT&CK techniques

6 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-06-29/gogs-cve-2026-52806-moves-from-no-observed-exploitation-to-a · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-06-29/gogs-cve-2026-52806-moves-from-no-observed-exploitation-to-a · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-06-29/gogs-cve-2026-52806-moves-from-no-observed-exploitation-to-a · ATT&CK page ↗

Execution TA0002

T1610Deploy Container×1

Adversaries may deploy a container into an environment to facilitate execution or evade defenses. In some cases, adversaries may deploy a new container to execute processes associated with a particular image or deployment, such as processes that execute or download malware. In others, an adversary may deploy a new container configured without network rules, user limitations, etc. to bypass existing defenses within the environment. In Kubernetes environments, an adversary may attempt to deploy a privileged or vulnerable container into a specific node in order to Escape to Host and access other containers running on the node.

Evidence: 2026-06-29/gogs-cve-2026-52806-moves-from-no-observed-exploitation-to-a · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-06-29/gogs-cve-2026-52806-moves-from-no-observed-exploitation-to-a · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-06-29/gogs-cve-2026-52806-moves-from-no-observed-exploitation-to-a · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-06-29/gogs-cve-2026-52806-moves-from-no-observed-exploitation-to-a · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-06-29/gogs-cve-2026-52806-moves-from-no-observed-exploitation-to-a · ATT&CK page ↗

T1611Escape to Host×1

Adversaries may break out of a container or virtualized environment to gain access to the underlying host. This can allow an adversary access to other containerized or virtualized resources from the host level or to the host itself. In principle, containerized / virtualized resources should provide a clear separation of application functionality and be isolated from the host environment.

Evidence: 2026-06-29/gogs-cve-2026-52806-moves-from-no-observed-exploitation-to-a · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-06-29/gogs-cve-2026-52806-moves-from-no-observed-exploitation-to-a · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-06-29/gogs-cve-2026-52806-moves-from-no-observed-exploitation-to-a · ATT&CK page ↗

Impact TA0040

T1496Resource Hijacking×1

Adversaries may leverage the resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.

Evidence: 2026-06-29/gogs-cve-2026-52806-moves-from-no-observed-exploitation-to-a · ATT&CK page ↗

Story timeline

  1. 2026-06-29Gogs CVE-2026-52806 moves from "no observed exploitation" to active cryptojacking campaign
    updates
  2. 2026-06-01Looking ahead — 2026-W23
    weekly-looking-ahead
  3. 2026-05-29Rapid7 publishes unpatched Gogs argument-injection RCE with a Metasploit module; maintainer non-responsive
    active-threats
  4. 2026-05-25Looking ahead — 2026-W22
    weekly-looking-ahead

Where this entity is cited

  • weekly-looking-ahead2
  • active-threats1
  • updates1

Source distribution

  • attack.mitre.org5 (29%)
  • bankinfosecurity.com1 (6%)
  • cpomagazine.com1 (6%)
  • helpnetsecurity.com1 (6%)
  • ic3.gov1 (6%)
  • isc.sans.edu1 (6%)
  • keycloak.org1 (6%)
  • ncsc.admin.ch1 (6%)
  • other5 (29%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

All cited sources (17)

Entries about Gogs argument-injection RCE (4)

2026-06-29 · view entry permalink →

HIGHCVE-2026-52806exploitedupdate

Gogs CVE-2026-52806 moves from "no observed exploitation" to active cryptojacking campaign

UPDATE · originally covered CVE-2026-52806 — Gogs self-hosted Git server: argument injection to OS command execution (BSI critical batch) (2026-06-20)

When this brief first covered the Gogs argument-injection RCE CVE-2026-52806 (branch name injects --exec into git rebase; fixed in 0.14.3 on 2026-06-07), exploitation status was not observed. Wiz Threat Research now reports the flaw under active in-the-wild exploitation: a cryptojacking campaign active 2026-06-13–23 chained Gogs and Argo Workflows vulnerabilities for initial access, compromised thousands of Linux hosts, and pivoted across more than 300 additional Kubernetes nodes (Wiz Threat Research, 2026-06-28). The new development is the exploitation, not the bug — the CVE mechanics and patch were covered on 2026-06-20.

Per Wiz, once on a node the operators stole Kubernetes service-account tokens and used them to schedule workloads cluster-wide, then escaped to host via privileged containers to deploy cryptominers; Wiz designates the actor "Unknown" and names the C2 framework "Realm C2." The Gogs argument-injection vector is the same one documented by Rapid7 — an authenticated (effectively unauthenticated on default open-registration instances) RCE via a malicious pull-request branch name during a "rebase before merging" operation (Rapid7 Labs). ATT&CK chain as reported: T1190 (exploit public-facing Argo Workflows / Gogs) → T1078.004 (stolen K8s service-account tokens) → T1610 (deploy container) → T1611 (escape to host) → T1496 (resource hijacking).

Defender delta since 2026-06-20: the patch urgency is now exploitation-driven, not advisory-driven. If self-hosted Gogs is still below 0.14.3, prioritise the upgrade and disable open self-registration (DISABLE_REGISTRATION = true). Hunt K8s API-server audit logs for create on workflows.argoproj.io and on pods from unexpected service accounts, git rebase child processes spawned by the Gogs service user, and privileged-container/nsenter activity. Enforce Pod Security Admission (restricted) and audit RBAC to remove default service accounts with node-escalation rights. Scope/attribution figures (thousands of hosts, 300+ nodes, "Realm C2") are Wiz's single-source assessment

UPDATE (originally covered 2026-06-20): When this brief first covered the Gogs argument-injection RCE CVE-2026-52806 (branch name injects --exec into git rebase; fixed in 0.14.3 on 2026-06-07), exploitation status was not observed.

ctipilot v2 brief (migrated)
vulnerability29 Jun 04:47Zmulti-sourceOpen finding ↗

2026-06-01 · view entry permalink →

NOTABLE

Looking ahead — 2026-W23

A focused, justified list — not predictions, but items already in motion.

  • June 10 — Patch Tuesday: Chaotic Eclipse patches expected; researcher promises a "big surprise" the same day. YellowKey (CVE-2026-45585, BitLocker bypass via WinRE autofstx.exe), GreenPlasma (CTFMON SYSTEM escalation), and MiniPlasma (CVE-2020-17103, cldflt.sys Cloud Filter LPE) remain unpatched as of 7 June. Microsoft is expected to patch some or all in the June cumulative update. The Chaotic Eclipse researcher has explicitly promised a new disclosure to coincide with June Patch Tuesday — prepare for a simultaneous patch-and-new-zero-day drop. Pre-stage: verify YellowKey mitigation applied (WinRE autofstx.exe removal script or TPM+PIN BitLocker enforcement); monitor Microsoft MSRC on 10 June. (Help Net Security forecast; CPO Magazine)
  • June 11 — CRA notifying-authority deadline AND FIFA World Cup kickoff. The first hard CRA milestone (§8) and the peak Ghost Stadium PhaaS threat arrive simultaneously. Ghost Stadium — a Chinese-speaking PhaaS operation active across 4,300+ fraudulent FIFA domains — has already claimed an estimated 47,000 victims and up to $1 billion in losses ahead of the kickoff (BankInfoSecurity, 2026-06-05; FBI IC3 PSA260527). The SSO-clone technique replicates PingIdentity login flows — corporate SSO credentials are at risk if employees mistake a sponsored-search-result phishing portal for an enterprise login. Defenders: add FIFA-themed domain alerts to email-gateway and DNS-filtering, block fifa.com typosquats at the proxy, and brief staff on avoiding paid/sponsored results for sports ticket purchases.
  • June 15–17 — G7 Évian summit: pre-stage DDoS mitigations now. NCSC-CH expects hacktivist disruptive cyberspace operations on each summit day, following the NoName057(16) pattern from Bürgenstock 2024 (NCSC-CH). Organisations in the Geneva–Vaud corridor and Swiss federal/cantonal SOCs should verify DDoS mitigation playbooks, review MFA on customer-facing identity providers, and rotate administrative credentials before the event window.
  • Gogs argument-injection RCE: still unpatched, Metasploit module public, 319 European instances exposed. The Rapid7-discovered pull-request-merge argument injection flaw remains unpatched; the Gogs maintainer has been silent since acknowledging receipt on 28 March. The Metasploit module availability means this will appear in opportunistic scan-and-exploit campaigns. Any internet-facing Gogs instance should have open registration disabled and the "Rebase before merging" strategy restricted to trusted owners. (Rapid7)
  • Keycloak 26.6.3 rollout: CVE-2026-9704 token-exchange priv-esc and CVE-2026-4874 SSRF are immediate patch priorities for internet-reachable instances. Any e-government SSO, SAML federation, or OIDC brokering service running Keycloak < 26.6.3 should complete the upgrade before the G7 event window. (Keycloak; daily 2026-06-07)
outlook01 Jun 05:00Zmulti-sourceOpen finding ↗

2026-05-29 · view entry permalink →

HIGH

Rapid7 publishes unpatched Gogs argument-injection RCE with a Metasploit module; maintainer non-responsive

Rapid7 Labs disclosed on 2026-05-28 an authenticated-RCE zero-day in Gogs, the open-source self-hosted Git service. The root cause is in the Merge() function inside internal/database/pull.go: when the "Rebase before merging" strategy is invoked on a pull request, Gogs passes the source-branch name unsanitised to process.ExecDir, bypassing the safer git-module wrappers. An attacker creates a branch named e.g. --exec=<command>; when git rebase runs, that flag is interpreted as a --exec argument and the command executes under the Gogs service account. Affected: Gogs 0.14.2 and 0.15.0+dev (commit b53d3162); all prior versions that support the rebase-merge strategy are likely affected too. The maintainer acknowledged the report on 2026-03-28 (reported 2026-03-17) but has not shipped a fix; Rapid7 published after the standard 90-day window expired. Rapid7 also released a full Metasploit module covering Windows and Linux targets. Shodan shows ~1,141 internet-facing Gogs instances. Class is CWE-88 argument injection — same technique family as CVE-2024-39930 / 39932 / 39933 in prior Gogs disclosures. The Hacker News writeup corroborates and adds that no admin privileges are required, only account creation and repository access.

Why it matters to us: Self-hosted Gogs is common in European public-sector code and research infrastructure as a lightweight GitHub alternative. Until a patched fork (Gitea / Forgejo) is adopted, set DISABLE_REGISTRATION = true in app.ini, disable the Rebase before merging strategy under instance settings, and watch for git child processes carrying --exec under the Gogs binary's process tree (Sysmon EID 1 / auditd EXECVE).

An authenticated Gogs user can achieve remote code execution on the underlying server by exploiting an argument injection vulnerability

Rapid7 Research

The flaw exploits argument injection in the git rebase command during merge operations by injecting the --exec flag. No admin privileges are required; attackers only need account creation and repository access

The Hacker News
threat29 May 05:00Zmulti-sourceOpen finding ↗

Earlier coverage (1)